Sign inSign up
regctl

dhi.io/regctl

regctl 0.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

0-alpine3.23-fips-dev, 0.11-alpine3.23-fips-dev, 0.11.6-alpine3.23-fips-dev

Index digest:

sha256:3e4976b06efe9eed42b5682819869fad9e6c96237496fd54d6826c6b476750b2

Manifest digest:

sha256:e5e9d5662e1d8438a3281d867b1f237232ed876d75b7cfef517937a7f30f1e0e

Size

13.00 MB

Last pushed

20 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/regctl:0-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/regctl:0-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/regctl@sha256:bd1ba996649d2963f82af063dbb11f2ff0b82fce2f6ccc106047947113a9db98
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/regctl@sha256:cabbd0e1a4bde3e97b2bbe528a43e212bfd8696ed5bd4787b632d2c7ec22cec3
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/regctl@sha256:d2d4c1809ff37189466b775c48c5a5014d8d6e54666e88b2620b845548ad98f8
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/regctl@sha256:6da3b3d735d4e961eb05651dd34bad02ae5e0a21ed520b5c35d92642b8cc04d1
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/regctl@sha256:b4966ff16cfbdb17c1413989390ef543014ea7a828b195198c199db3ac88774f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/regctl@sha256:5637395b93e0fc395b135198de895839c6a65d4ae4fa381e7b8a07f8af2836aa
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/regctl@sha256:bd07318c0a6e56b794326a2f095305c89b4edd0c7fa9877bb31c54f1930292fb
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/regctl@sha256:7ac842e135da43cad46390774200281ff530df2e03dc8042c657d522ab169b1e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/regctl@sha256:03267fa6d168034ab4eb85e89952f371972123a4608b82a690baeb193908a592
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/regctl@sha256:e0561ad58f16b238fd9164c0751a82412334a033ee16ca2477d47da359ddc871
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/regctl@sha256:81eb9240a1e792790af47d87b2464edbafda15f550f89aa530d83558d9eda782
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/regctl@sha256:faf9bad39ed920c5fc8ebd7bca87c17ff693da7d3ac4fb78d13e7d443d6191c6
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/regctl@sha256:a503ad1afc1c56c492329d932c43065c3d4ea8f5d123554f81802bb21d6d16fb
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/regctl@sha256:df02071399f93e27e0412e75a36c2c9b0447c8d86796e7cdadf23a132e9baef0
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/regctl@sha256:12a74af41c1bea2fdc30194dba64bd48540fdffb82e86a07d0633493693c04e1
SPDX SBOMhttps://spdx.dev/Documentdhi.io/regctl@sha256:347cf0fab1f5ba1ae85c0d2ba010919fc383179b4a8a55cb34c7663238a80ac3